Integration
Intelligence
Secure Document Portal
Data Handling Policy
Version 1.1  ·  June 2026  ·  Applies to all client engagements
← Back to portal

At a glance

AI data retention
Zero — prompts not stored after processing
Training on your documents
No — zero-retention API configuration
Document deletion
Within 14 days of report delivery, or on request
NDA
Signed before any document transfer
Third-party access
None — Anthropic API only, disclosed below
Cross-border transfer (GDPR)
Anthropic API — US infrastructure. Zero-retention DPA available.
Formal DPA
Available — Anthropic API DPA provided on request
Secure transfer method
Secure link only. No email attachments.

1 What we do with your documents

The Integration Intelligence Engine is an AI-powered advisory tool that analyses M&A deal documents — board packs, due diligence reports, synergy models, and integration plans — and produces an integration readiness assessment. To do this, we need to read the content of those documents.

Document content passes through three stages:

Stage What happens
Document receipt You transfer documents to us via a secure link. Documents are stored encrypted. Only the named engagement lead has access.
AI extraction Documents are processed using the Anthropic Claude AI service (see Section 3). This is where deal content is read and structured signals are extracted. This is the step that requires the most careful disclosure.
Report generation Your analysis is converted into a report using deterministic code and a second AI step that operates on structured data, not your original documents. The original documents are not re-read at this stage.

2 Who has access to your documents

During the pre-pilot period, each engagement is handled by a single named individual. No team, no offshore resource, no automated pipeline with unreviewed access.

3 AI processing — Anthropic Claude

All AI processing steps — document extraction, optional gap-fill survey, and synthesis — use Anthropic's Claude models accessed via the Anthropic API. No document content passes through the claude.ai consumer interface.

API access is configured with zero data retention, meaning prompts and completions are not stored on Anthropic's infrastructure after the processing call completes.

Aspect Position
Training on your documents None  Zero data retention is configured via the Anthropic API. Anthropic does not store or use API inputs for model training under zero-retention configuration.
Retention on Anthropic servers Zero  Prompts and completions are not retained after the API call completes. No conversation history is held on Anthropic's infrastructure.
Anthropic staff access Under the API zero-retention configuration, Anthropic's standard rights to review conversation content for safety purposes do not apply — there is no stored content to review.
Formal Data Processing Agreement Available on request  A formal Data Processing Addendum (DPA) is available from Anthropic at the API tier. This can be provided to clients as part of the sub-processor disclosure.
Data jurisdiction Anthropic is a US-based company. Document content transmitted to the API is processed on US-based infrastructure. GDPR-scoped clients should note this as a cross-border transfer, mitigated by the zero-retention configuration and available DPA.
Plain statement: your documents are read by an AI service operated by Anthropic. Under the API configuration we use, Anthropic does not retain your documents after processing completes, does not use them for model training, and a formal Data Processing Addendum is available on request.

4 Infrastructure & technical controls

The following technical controls apply across all components of the service:

Control Implementation
Document storage Encrypted at rest via Supabase Storage (EU West — Ireland). Private bucket with Row Level Security. No public access.
Transit encryption TLS 1.3 on all connections — client portal, document upload, and API calls.
Portal access Token-based magic link. No user accounts or passwords. Each engagement has a unique link with a defined expiry. Links are invalidated on delivery.
Data residency (storage) Supabase EU West region (Ireland). All stored documents and deal data remain in the EU.
Access control Row Level Security (RLS) enforced at the database layer. Each portal token is scoped to a single deal.
Portal hosting Static HTML served via Vercel. No server-side code. No cookies. No tracking.

5 Our commitments

Before you share any documents, we commit to the following in writing:

6 What we ask of you

To allow us to handle your documents appropriately, we ask that you confirm the following before transfer:

7 Additional options for specific requirements

The standard configuration described above meets the requirements of most engagements. For clients with specific data handling constraints, the following options are available:

Document redaction before transfer

For particularly sensitive materials, we can agree a document preparation protocol — removing named individuals, specific financial figures, or counterparty details — before transfer, so the AI extraction step operates on a de-identified version.

Azure OpenAI processing

For clients who have already approved Azure as an AI sub-processor under their vendor management framework, the engine can be configured to route all LLM calls through Azure OpenAI Service rather than the Anthropic API. Azure provides equivalent zero-retention configuration and a formal DPA under Microsoft's standard data processing terms. There is no material difference in output quality.

On-premises processing

For institutional clients where all processing must remain within a defined jurisdiction or infrastructure boundary, we can discuss alternative architectures. This is a longer-lead option and would be scoped separately.

Please raise any data handling requirements before the engagement begins. We would rather have that conversation early than ask you to make a risk-based decision under time pressure.

? Questions

Questions about this document should be directed to your named engagement lead before any documents are shared. You can also reach us at jon@integrationintelligence.co.uk.